The useful production lesson here is that rm changes namespace state, not necessarily storage state. That also explains why df vs du is such a valuable diagnostic combination: when they disagree significantly, deleted-but-open files are one of the first things worth checking. I’d also treat truncating /proc/<pid>/fd/<fd> as an emergency recovery technique rather than the normal fix. The safer long-term solution is getting the application’s log lifecycle right log rotation, reopening descriptors, and monitoring filesystem headroom so a runaway log doesn’t turn into a 2 AM storage incident in the first place.